Government 
Publications 


Canada. Office of the Auditor General 
Auding what isn't 
(Discussion paper no. 36) 


Te 


Governmacst 


2 Bureau du 
Ke vérificateur général 
du Canada 


Office of the 
Auditor General 
of Canada 


DISCUSSION PAPER NO. 36 
AUDITING WHAT ISN'T 
by 


Dan Rubenstein 


August 1984 


DISCUSSION PAPER SERIES 
DOCUMENTS DE DISCUSSION 


The attached paper has been prepared to stimulate Le document ci-joint vise a stimuler la réflexion et la 
thought and discussion regarding our audit discussion sur nos activités de vérification. Les 
activities. The views expressed are those of the opinions exprimées dans ce texte sont eelles de 
author and therefore should not be construed as l'auteur et, par conséquent, ne lient pas le Bureau. 
those of the Office. 


Your comments would be appreciated and should be Vos commentaires seraient appréciés et vous étes 
directed to the attention of the author. priés de les faire parvenir a l'auteur. 


Additional copies of this paper, or other papers in Vous pouvez vous. procurer des exemplaires 

the "Discussion Paper Series", may be obtained supplémentaires de ce document ou des autres écrits 

through the PROFESSIONAL PRACTICES GROUP. de la série des "Documents de discussion" en vous 
adressant a la DIRECTION DES METHODES 
PROFESSIONNELLES. 


OV ert 


Publeamect) 


DISCUSSION PAPER NO. 36 
AUDITING WHAT ISN'T 
by 


Dan Rubenstein 


August 1984 


Digitized by the Internet Archive 
in 2022 with funding trom 
University of Toronto 


https://archive.org/details/31/761115503625 


Auditing What Isn't 


According to the Comprehensive Auditing Foundation of Canada, a 
comprehensive audit is an examination that "provides an objective and construc- 
tive assessment of the extent to which (1) financial, human and physical resources 
are managed with due regard to economy, efficiency and effectiveness; and (2) 
accountability relationships are reasonably served". A comprehensive audit, 
therefore, examines both financial and management controls, including informa- 
tion systems and reporting practices, and recommends improvements where 


appropriate. 


That description of comprehensive auditing is fine, but I believe it 
does not go far enough. The definition assumes the existence of management 
controls, but what if they do not exist? This article argues that comprehensive 
auditing should also be concerned with the absence of expected management 
controls. In short, if auditors suspect that a control that should be in place is not, 
the first step is to prove its absence, the second to quantify the impact of the 
lack of that control, then to determine the cause and, finally, to make appropriate 


recommendations to the management involved. 


"Using models to gain the knowledge of business necessary to compre- 
hensively audit what is, as well as what isn't". 


The key to effectively discharging these audit responsibilities is a 
dynamic and well-integrated knowledge of the business. The required knowledge 
blends the realities of "what is" with a preconceived sense of "what should be," 
that is, it combines descriptive realities and normative models. Auditors 
therefore audit what isn't, as well as what is; that is, they audit the less obvious 


sins of omission, as well as the more traditional sins of commission. 


A useful technique for such an approach to comprehensive auditing is 
modelling because it provides structure for a comprehensive audit while 
recognizing the uniqueness of each entity. Modelling evolves from a preconceived 


notion of how the audit entity should ideally be operating to maximize the 


7 head Oe 
rn ae 
ys a - 
| - 


« ,gtar8l t& tone mikey = oenees 
rages (fe cv rayseetes fe (ivon’ col UAT 
Pit \alormr't (() site 
oe ere Ne lin ¢lserwhin visitor ie a0 


Jit, sv aner } wre, | + We al 


ars e ——e ; ‘ al 


a: 9 oil ates | 6 pl n> 19 Peleg raed 
: =~ We a eres ‘ aA* ott “ aa, s ey 


ante ia ne Hott Hee Te 
—s : w&y 3° 9 : . .- ipietets 


& ius iri = ae tg at 


’ , Gen oi en Fey, 


0 74 ED i be > ae “yy eettendl 
id T eer 


- 
lial 22 otal o al rep oF iJomnag or. 


Ave’ as oa ls 


' é ee Me hoe, PL 
yres! vy pe @ 0 Sel] i¢ be ’ Db aS Ai wo 7 
vo . P : a0 ory 
ts - 1S > ot ek eo 0 > t . 
; a : ” o 


5603 £ — ewi aris nq (ea taps “we ye HH), 
eee ee ee ee 


fe ee kar ah =f 


Se aaentemeneiiel 


delivery of results and minimize waste. By comparing the actual operation with 
the model, the auditor can identify and subsequently diagnose deficiencies in the 
operations of the entity. 


What is comprehensive auditing? 


If we review the definition of comprehensive auditing given at the 
beginning of this article, we find that it emphasizes "due regard to economy, 
efficiency and effectiveness". Simply stated one of the objectives of a compre- 
hensive audit is to identify opportunities for the government to achieve the best 
services for the money spent and to make constructive recommendations on ways 


to improve any wasteful practices noted. The audit, therefore, will normally 


focus on: 

* Lack of economy -- caused by, for example, purchasing goods at the 
wrong time, at the wrong price, of inferior quality, or in the wrong 
quantities, or by failing to obtain sufficient revenues for services 
rendered to the public. 

& Lack of efficiency -- caused by using too many people and other 
resources to produce too few results. 

& Lack of effectiveness -- caused by doing the wrong thing altogether. 


In contrast to financial auditors, comprehensive auditors do not start 
with a set of financial statements or well-defined reporting conventions (GAAP). 


Rather, comprehensive auditors have to: 


e Address "softer" management issues where there are few commonly 


accepted ground rules on how to achieve results. 


® Identify the rules or criteria, to be used to evaluate the data collected 


relative to each issue. 


peda isoe rah 


ayn ee 
Pols Wate ok sueeae 


i a= "ss = hae. cpprmeet ot 


~ 
S 


2? (> Poe ous ass. 5d oka 
aie Reo ong te ALG SE pellet pene 
“a ed aa os id 1? Dpttinat | 

ih WEP Hesbiet: 


Hien ieee eal! a Qe oe pee - Cae te em 
Dia CA lel cet Gr ee ore 
9 
EINER bP WHS (AN! WS Me Oa - sees te nk 
ei eee ee * 
re? orves" cents. emaalaa 
2 ene? afibue wiaglingnas a. 


> afl om id Daye ho) Tania “eat 
Ae wis a oe aaa hang § 


inch ig aa scene 
2 
7" feo : 


nee 


® "Sell" their opinion, that is, present the opportunity cost of not 
following recommendations on how to achieve greater service for the 


same cost, or the same level of service for a lower cost. 


Preparing a model of the entity helps comprehensive auditors gather, 
organize and communicate the dynamic knowledge of the business required to 


successfully meet those audit challenges. 
Required knowledge of the business 


During the crucial planning phase of a comprehensive audit, it is 
essential that auditors acquire a knowledge of the particular entity being audited, 
as well as a general familiarity with the industry in which the entity operates. 
That knowledge must be broad, accurate, thorough and incisive. Auditors must 


determine: 

e What business the client is really in. 

Fa The essential elements of the business, the infrastructure of the 
business, the crucial interactions that transform resource inputs into 
desired outputs in the form of products or services and the operating 
environment. 

% The control framework established by auditee management. 


The auditor first addresses the basic question: "What business is the 
client really in?" The need for this clarification usually arises in public-sector 
comprehensive audits of a department or program. A multiplicity of goals, 
objectives or activities often obscures the entity's raison d’étre. Consider, for 
example, a lender of last resort making economic development loans to socially 
disadvantaged groups. Is the program in the welfare business or the loan business? 
As the audit approach will differ accordingly, auditors need to identify the real 


business. 


Mt) e== erent @'s ieee! eee on hand 
Ek chrted 26 @G & 6 adie oot tag fa8 hs 
ras AI BM oDu Hi renee -oNr ogee @amey 4 ue 
SOF hy » “Snr B- Oe Cys olay zo phd 0 thas ggyiairel 


~ ini s?* ith bt) ertat o®@ 


| — 
dn-4e Genenery: BY Senet tt | ina ieee 67 
a ee 
oeetadtian Ss ley eit 'S cremate ned wiry Capes Came 
ese es 


=) eet Sle cele ered eae | 


SO WORN IBS OS em" OH # (ot? estat 
rope (Dy ethan) @tL6. ail. 2 Oy re ate “tal yllnve 
obese > Gee 45> ewe cfigt «th eae 
$2 nes ari sun.) an ep ae & 
Sire Ab ee" =o cet 6 gen eo te 
Repeeg sat sh! - conjet xt? . of arene as o@ copamenbal 
ey A Th ey) cet, Eo 6 iy hi wt un marane es a mh 


As well, the essential elements of the program must be clearly 


defined. These elements include: 


° The entity's mandate and any related authorities; the why of its 
existence. 

6 The entity's operating environment and key opportunities and 
constraints. 

& The entity's organizational structure and modus operandi. 

@ The entity's principal program delivery systems. 

® The entity's principal results in terms of products, services or general 


benefits, as well as the principal types of resources consumed to - 


achieve these results. 


The auditor then reviews the management control framework estab- 
lished by auditee management to ensure the utilization or resources in compliance 


with managements' objectives and goals. 


That information becomes the raw material for the development of an 
appropriate audit model. Such a model helps auditors organize a vast and at times 
confusing array of facts and bring order to their comprehension of the entity's 
organizational structure and behaviour. Because the model provides a common 
basis for understanding the organization, it serves as a useful means of communi- 


cation within a multidisciplined group of auditors and between the auditors and 


auditees. 
What is an audit model? 


Webster's dictionary defines a model as a "description or analogy used 
to help visualize something (as an atom) that cannot be directly observed". A 


model, therefore, is an abstraction, a simplification of a complex reality. It 


fie 


‘Se * 


| . : 
ee 


CP  ) are res pans : it 


- 
Boe TEMS ow i pe sem ieREO wr EAN BET 
wil be: net mane ged eg 


- 
lieing da tts’ ef). <4 = = svpeey ee ad 7 tng ary, 7 
= a sqprerGiite uiem |p ii @t) = hee & eileent-e 


, Peet OY Gears 
8, arg a Gtias Sm > re ee - 
er ue owe sy or 9 GUnboatgne, gusts 


ee 


fs De-e em PGR e. em) ee pepeaeed NENNNSIG AFT 
$4108 470-9 toip ¢ ther oie = At 0 OUR, > tae 
otis Ni | Anamepret God © Sais peat wim apa ‘to yar 
hie P= | en = ot eg sed (aeted hep ecgarcit in 

Si i Se Oe 1 Speke y ow gainatevonts a 5 
Sms eee 65) viene! Org mee, 6 A Seinen li aie 


. / 

a ee ne ee ’ 

DD Seta sit Eat eee gi i a 
File \eyen 2 eee ini Goeeeteee gow: 


_ 


a a 


assists in identifying key elements of the thing being described, as well as illus- 
trating the interrelationships between those elements. An audit model is a 
simplified description, a concrete representation of the audit entity. It attempts 
to portray a comprehensive, dynamic overview of organizational activities. A 
successful audit model portrays those interactions in a manner that logically 
reflects the sequential flow of essential transactions, focuses attention on the 
important "driving" forces, defines the roles of the principal players and highlights 
the key management and financial controls at each step of the process examined. 


Models used to identify a lack of controls must be more prescriptive 
and dynamic than those used in the more traditional form of audit - for example, 
the flowchart. In this sense they more closely resemble "standard" Internal 
Control Questionnaires which lead the auditor to compare controls which are in 


place with those which normally should be in place. 
The modelling process: an example 


Conceptually, the modelling process involves two distinct phases: the 
development of a descriptive model that documents what "is", and the develop- 
ment of a predetermined control model that documents all the controls that 
"should be" in place to ensure the program or activity is operating properly. The 
predetermined control model contains the standards, or criteria, through which 
the actual auditee operations will be evaluated. The modelling process can be 
best illustrated by using a hypothetical case study of an audit - the previously 


mentioned government loan program. 


The auditors' starting point during the planning phase of the audit is, 
as noted earlier, the question: "What business is the loan program in?" The 
auditors review the program's mandate and practices. After finding that the 
program, in fact, actively pursues loans in default, the auditors conclude that the 
entity is really in the loan business, not the welfare business. The auditors' 
efforts to gain the necessary knowledge of the business will then lead them 


through a bewildering array of statutes, financing instruments, political factors 


witcivess) er ag te ected 
tdipraee WO) - Cae 16 fi 
ied Svea: Airepets reels Gtatgy e | Uwe: 
% Pe ne wire) amnNte> & 


ef! =e See eet BENE’ legen ate | ia qn? 
_cidevonm a tom, Sa” 50°6. SeAerE eee eS aee & re) 
amr el~2the ge i vewndse : 9; 


7). =a: gevey # [wns © ne . OP igcgie Ss. er Wi 
As (eert Sariowe send r=wrn 7 - Cae wD orwi 
‘ei sae pallet Gee patsd hi eer i 

iositer en ©) = alum fie Tete at @ a 0 Q06e8' 

: Depmenree rg ve 

? 

he ae | 7 Wess iined 447 
a 4 ote ae oe wd ee cuicesep ori alee 


0% ae gue Gelh ih ne emirgos © ore 
CMe <aty en ob ae COUR Write SIs’ 6 
yen 210 «peel @+ 300. Grwipet nea! am fy wire: 

n-  ged coe die ephage at Seema em. 
ere ioe, werent, ree are WEE. Gewoies © 


SNOILIVSNVUL 
SLYOd3N 
/ INDIHD SILINM 


SINIWAVd 
JLV1 SJLVOILSIANI 
/$S11ISOd3O 


NOILVINIDNODIY SGYV) NVOl 
ATHINOW TWWIDISIO SNIVINIVIW 


dN-MO1104 
/NOILDIT1IOD 


SNVO1 39UVI 
AYAN SINOUddV 


TIVWS SINOUddV 


JDYV1SIANOUddV 


NOILIVSNVYL IWIIdAL V JO FIDADIAN 


AINIOV IWYLNID 


193fOUd SILVILINI 
¥391440 NVOT 


S153NOIY 
T1W SM3IARY 


INILISNAS SILVILINI 


LINN TWNOILVZINVOYO 


L31ISVL 


WV¥9OUd NVOT V JO TSGOW JAILdIYDSIG 


= . 7 
: ‘ht ivan = 
rin 


| b _ - 
ox i; i i ae Shelter = = = e= —_—_-e ha —— Be ae Ga 
: “ 


a 
7. 
ae: 


= 


Fisersezsteahs | peasy 2zyeentiA 
MAG: 


a : 
a a ee | eee =e FF 


| Beomsestumirer PAY aes en ai . 
| . TA 33 reat 7 


- - a a 
— am es Ue cll e-<«@ -o2 @& es pip > - aes &S eS = B® DS 


edie ashore Cay ete, © ari ' TMA 
fino en ered 1@AS 
Ne eA o— : 


eee ee Sen een EE 


and transactions spanning various organizational units - districts, regions, head- 
quarters and central agencies. Faced with a potentiai overload of apparently 
disjointed data about the who, what, where, why, when and how of the program, 
the auditors will search for an appropriate framework to organize the information 
gathered. Cognizant of the reality that it is impractical to model everything, the 
auditors will determine an appropriate level of detail for their model. 

: 

Building on their previous audits of financial organizations, the 
auditors will decide that the logical starting point is the universal life cycle of 
any loan: initiation, approval, disbursement, collection, follow-up and write-off. 
They visualize a matrix, such as in Exhibit 1, that juxtaposes and matches those 
phases of a typical loan transaction with the key organizational units involved - 
headquarters, the regional offices, districts and applicable central agencies. For 
each box in the resulting matrix, the auditors will fill in a brief description of the 
activity performed and the control currently in place. At the end of this initial 
phase of modelling what "is," the auditors will have identified the controls on 
which management currently relies. This is illustrated in Exhibit I, Descriptive 
Model of a Loan Program. They will then test those controls during the execution 
phase of the audit, followed by a report to management on whether the controls 


are effectively preventing waste. 


In the second phase of modelling, the auditors stand back and ask, 
"What additional controls should be in place?" at each phase of the life cycle of 


the loan, to ensure that: 


@ Loans are made only to viable businesses unable to obtain alternative 
financing. 

& Loans are properly challenged and analysed prior to approval. 

& Loans are disbursed only after security on assets is properly 
registered. 

e All loan payments are collected and deposited and late payments are 


followed up in a timely manner. 


oo qeagey't 
2 Sisvi hen 8 cei 
‘bars &. Ge P 
sw seco Op Gun a 
642m Ch & : we 
o¢ sie igs : a ids Ls 
oe oe ee.” ; : | ee 
ow eee ot ay o a 2 ¥ 
= p ome. p Galea, ome ling 
a a ol oth = tip mh 
a 
22? 266s haere Vay 


ii) 


s a erteuaste’ ee a i - 
tm sooner ii 
: 7 

> S epee Gere <> 3°! 
28th Grores beet. 

(4 um vies 


way Wee: coe FR ou se 
+ es a) 


= Gag am vu ims 
era) 


= : 
eee 
_ 
> 
ae | = 00 of remy? mete Gee Merweis we rac) ° 
7 Srattins: 


ee aetna » 
7) mr 


a. , Lie is atk 


SNOILIVSNVYL 
SLYOd3I¥ 
/ INOIHD SALIGM 


SNVO1 49DUVI 
AYSAA SANOUddV 


SINIWAVd 
JLV1 SILVOILSIANI 


eal 


NOILVINIDNODIY 
MIHLNOW 


dN-MO1104 
/NOIL3311059 


JNOIHD) SILNIYLSIG 


SaYv) NVOl 
1WWID1d4dO SNIVINIVW JOUV1 SIAOUddV 


NOILIVSNVUL TWDIdAL V JO JTDADIIN 


IOYLNOD ONISSIN [ff] 


ADNIOV IWYLNID 


1335fOUd SILVILINI 


(‘= 


LINN IWNOILVZINVOYO 


73198V1L 


INWHOONd NWO1 W 4O 1300 1ONLNOD GANIWYILIGINd 


Ss 2 2 «2 = & S&S a> & 


IAVORTA WoT AIAN 
Pee Say = oe PLS Ge = <=> : —— a ee 


| JAGAN elAT EA: | ino eons | ier errata 
CMA BRD) an oo ea) 


a & aS) = @ ee aw 


_ 7 


ay CMA 


: + 
a ol hee ie 


- pal Se ee a eee ey 
: 2 ua PIT yeeiiaG 7 LUMO TI aT - 
¢ 
——Kt OS se & ee ee -_— = eS as = Ss Se ee == —-w = em oe > 
wie \ SUD PT yom 2wonma | Aq" CoMmaA lanielgp 
STROH . EN AD) JaeG) 
PN BT IASHART . | : i 


aie 


It is this second phase of the modelling process that poses a unique 
challenge to the auditor and requires an ongoing and continuous process of 
collaboration and communication between the auditor and auditee. The auditor's 
dilemma is that he runs the risk of losing his objectivity and independence by 
getting involved in standard setting, rather than auditing. However, the purpose 
of this second phase is to identify potential gaps in management's established 
control framework, the existence of which will be proven, or disproven in the 


auditor's subsequent field work. 


During that phase of the modelling process, the auditors draw on prior 
experience with other financial institutions, the formal procedures of similar 
organizations, discussions with auditee management, and general principles of 
sound financial administration. Controls that the auditors and management think 
should be in place to prevent waste form the basis of the matrix shown in Exhibit 
2. Missing controls, such as the preparation of a formal viability report, are . 
shaded. That mode! will provide a norm, or benchmark, against which to measure 
the entity's actual control practices. 


The Field Work phase 


Starting with the predetermined control model developed in the second 
phase of planning, the auditors proceed to the execution (field work) phase of the 
comprehensive audit. They draw up an audit plan to (1) test whether key controls 
operate as designed and are effective and (2) gather sufficient appropriate 
evidence to support an analysis of the cause and effect of significant weaknesses, 


deficiencies and inefficiencies. 


Now the auditors perform the traditional audit procedures designed to 
test compliance with existing management controls. Then, they go one step 
beyond: they audit. the controls that they know do not currently exist but that 
they believe should exist. Their audit objectives, relative to each potential 


deficiency, are threefold: 


7 


ar) | - 7 ao 


o - 
00 ip ie a 3 


a" ma ; n° a 
weenlarer a pine wer 7 sev ae it - 
more Ls Ny ee oe : 


aa 
feet ‘pi meng) bynes * 
See ete A cso aned oi pipet! le 
ian the een a 


Se ee er ee ee | 
be ae RenUiencrd, fers mit eealterin |\néeG, +siin wee Gat | 
te pilghinieg inten AE crneivie gwar a he Hie enninecls jane) ail | 
AE FosPNpRMON ON senied Oi Lott cent ge oi=pe laren b 
SARE cha SEpe BS Ye pital oH inset Stcew Sifee@ey 3 enela nh ath | 
ate Soqe yiiingiy Pe Olt ert ar 7 @ $22 neta uel 7 . 
OneErE oO) dvi RAINES Ginsoned = yeh worm Ve shown tat velo» | 
Se agae IWR beet eh ayia ae | 
ae 
SPAs Ca tell aff | 
| 


4 


Pree eritct heeclerad dehy jear=. Laninredete we get? FE ga eh 

aw 1 SeBA: (strow Mg tS) Mer iiise= oe (Jit <4 .ovrala Io peste 

SLE GnGD YOU tether Sem (05.00 male bibith hay cede Gants Silas welinedetattion 

a orga Ineiniline wartter Ti) tre sect =) Give teraceeh @f o1g9ée0 

sr teeeine tee niiingit to: lte tee ane” wi lpmeth Whe oon ar seine 
(aie eho" towe gions 


Ot bergen eocpetern, fem Lartiticuey ii) Heel ee odd walk 

ene ee ay yet wer aietinr) Per age grcaixe rep soesibone> tent 
Farts Jit Petem ylenerits ton Sb wri) oH) jel ones aft) Sflek wei: baaved . 
dbisnerer res co Guitéie knyoseide Whur Yieth crate. bhocte srolimd: qoriy 


| 
Ndelere® esp opeminites () of 


aati ie: 


le To prove that the control, or relevant compensating control, does not 


exist. 
2s To prove that significant opportunities are being lost. 
3; To determine the causes and effects of the deficiency and make 


appropriate recommendations. 


In the example of the loan program, the auditors' predetermined 
control model indicated that a control should be in place to ensure that cheques 
are not issued before a chattel mortgage is registered. During the field work, the 
auditors will compare the dates of cheque requisitions to the dates of security 
documents, analyse loans in default for cases where registration was omitted and 
determine program responsibility for ensuring that all loans are properly safe- 


guarded. 


The final audit report will reflect the auditors' findings on the 
potential deficiency. Serious deficiencies compounded by cases of significant 
waste will lead the auditors to make recommendations designed to correct such 
omissions. The auditors will have audited a control that is not in place, and 
proved that it should be. The auditors' recommendation is not based on standards 
he has established, rather it is based on documented cases of waste that might 
have been prevented by a control not currently in place. Management then 


decides to set new standards, based on the auditors' findings. 
An endless variety of models 


The audit model used to examine the ongoing management of a loan 
portfolio would not necessarily be appropriate for other entities. The loan 


program was typical of matrix organizations. 


Entities characterized by hierarchical structures demand a different 
type of model, for example, one such as shown in Exhibit 3. A unique feature of 


that model is the series of top-down, cause-and-effect relationships that are 


a 


olay = emera.oar term 


pant 


on orem (5 oette 


_*" - 
Desskesunigiboaie 


2mets tom « sim 
id fuse yy SAT gel 
Pile Mes 


-_ Ss wore 2 wee Pid 


“tbs olen seh Geo 


-12- 


INIWdO13AI0 
3 NOISIG 


ONITIOYINOD | 3=~—™~—~C~«&YSt*Cté«ONTLT' ad 
1 
1 
== Sak Ae pe | SE 
$3198V¥3/AINIG 


NOILVLINIWIIdWI 


GQOHLIW 


IIDADIIN 


JILIIWWOD 
ONIYIILS 


(ID oh PN rd a | 
1 


AYIAINIO 
133fOUd 


WILSAS LOW 


133fOUd 


NV 1d 
YILSVW 


$$330Ud AIG 


GIYNLINVIS 


NOILVZINVOYO 
133fOUd 


133fOUd 
JIBVIA 


AGNIS 
ALINSISW34 


SNOISIDIO 
DIOILVYLS 


JILVONVW 


SLNIWIYINOIY 


WILSAS SO33N ¥3ISN 


~~~~T onzinvoyo [ ONINNV1d 
1 
i] 
Ale a Se oe Pe gee 
S3NOLSIMIW 


SOYVOGNVILS 


YIDVNVW 
133fOUd 


(ers es ees ee es eee ee ed 


7 
' 
J 
6 
é 
. 
$ 
. 
7 
= 


Ea hs ee 


implicit in its pyramid structure. It depicts a hierarchy of potential fatal 
mistakes. If a clear mandate is missing, there is a high probability that all that 
rests below it will not be well implemented. Similarly, the absence of a project 
manager with overall accountability and authority for the day-to-day management 
of the project suggests that the lower-level planning and controlling activities will 
not be well handled. Effective use of this particular model will provide the 
auditors with a road map during the field work that would lead them to ask the 
right overview questions, identify serious weaknesses in project management and 
link these weaknesses with verifiable failures in results. 


Good audit models 


In practice, there is an endless variety of specific audit models, each 
appropriate to unique audit environments. There are some common elements, 
however. A useful audit model should be self-correcting, relevant, simple and 
disposable. A good model is self-correcting because it leads auditors to ask the 
right questions and the answers to those questions lead the auditors to make the 
necessary revisions to their models. A good model is relevant because it focuses 
the auditors' attention on the important activities and outputs of the entity, not 
on peripheral or support activities. A good model is simple because it limits the 
number of potential choices, rather than presenting an unnecessarily complex 
array of issues to investigate. A good model is disposable because it does not lead 
the auditor to confuse the audit process with audit recommendations; it is a 


means to an end. 


In the case of comprehensive auditing, a good audit model helps 
identify potential risk areas caused by missing controls. Auditors then test the 
model against reality - their objective is to recommend improvements in the 
management control framework in place to ensure the government provides the 


best services for the money spent. 


‘ > - ; pe - ‘) 7 


| ath latneine ia or gger ane oc cnr MMi’ x 
ee W iat Fintwaaegre ! ‘ena 84 CO egy TeeD, W, 
(ATSC O22 es OY UG) amor me sony Vw 
jee —rGne* F4lace> Glieii we) o co ROTH awe 
Lie ae EIT 9s } “vent ah oe net agi! Gr@ | eeu © 


at era Dw A. ain . ‘cornet other in 


a 


4] Geb 4) Ate"). <4: |) wie Lo 46> £14) 
tae GR Agere: ai? 15 iu ony 
10 Wiles 
re 
PP =r 1 7 
ere ’ é 
17TRE ‘ 
ay. v6 ang 
¥ 5 Mu § 
= 5 as 9 
: 7 Bey 
" Ty Ss IF 
Os é 7 Sais 
j i ; 
: “ 


ae LA 


ACCOPRESS' <> 


25070 YELLOW/JAUNE BY2507 
25071 BLACK/NO!IR BG2507 
25072 BLUE/BLEU BU2507 
25073 R. BLUE/BLEU RP. BB2507 
25074 GREY/GRIS BD2507 


25075 GREEN/VERT BP2507 
25077 TANGERINE BA2507 
25078 RED/ROUGE BF2507 
25079 X. RED/ROUGE X. BX2507 
MADE IN CANADA BY/FABRIQUE AU CANADA PAR 
ACCO CANADIAN COMPANY LIMITED 
COMPAGNIE CANADIENNE ACCO LIMITEE 
TORONTO CANADA 


aT 


S Z29€0S 


